Record summary

CVE-2023-31446 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and executing it with root privileges on device startup.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 21, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 11, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Repository PoCs

GitHubDodge-MPTC/CVE-2023-31446-Remote-Code-ExecutionRepository PoCby Dodge-MPTCStars: 3Not analyzed3 files

127.5 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALCassia Gateway Firmware - Remote Code ExecutionCVSS 9.8

In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and executing it with root privileges on device startup.

Impact

Unauthenticated attackers can inject Bash code through the queueUrl parameter which executes with root privileges on device startup, potentially compromising the Bluetooth gateway and all connected IoT devices.

Remediation

Update Cassia Gateway firmware to a version newer than XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947 that properly sanitizes the queueUrl parameter.

AuthorsDhiyaneshDk
Template tagscvecve2023rcecassiagatewaycassianetworksvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:cassianetworks:xc1000_firmware:2.1.1.2303082218:*:*:*:*:*:*:*
Shodan: html:"Cassia Bluetooth Gateway Management Platform"
Shodan: http.html:"cassia bluetooth gateway management platform"
FOFA: body="cassia bluetooth gateway management platform"

Source: ProjectDiscovery

References

4